Directory Traversal Affecting grafana-postgres package, versions *
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-CENTOS8-GRAFANAPOSTGRES-2938061
- published 30 Jun 2022
- disclosed 6 Jun 2022
Introduced: 6 Jun 2022
CVE-2022-32275 Open this link in a new tabHow to fix?
There is no fixed version for Centos:8
grafana-postgres
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream grafana-postgres
package and not the grafana-postgres
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content
References
- https://access.redhat.com/security/cve/CVE-2022-32275
- https://github.com/BrotherOfJhonny/grafana
- https://github.com/BrotherOfJhonny/grafana/blob/main/README.md
- https://github.com/grafana/grafana/issues/50336
- https://github.com/grafana/grafana/issues/50341#issuecomment-1155252393
- https://grafana.com
- https://security.netapp.com/advisory/ntap-20220715-0008/